How Risk Classification Works

What happens between your answers and your result.

Guardia AI's risk classification is a rule-based mapping from your answers to the EU AI Act's own decision structure — not a black-box AI guess.

The pipeline

  1. Prohibited check (Art. 5) — your use case is screened against the banned practices first.
  2. Annex III mapping — your sector and use case are matched against the eight high-risk categories, including the sub-conditions that distinguish, say, "CV screening" (high-risk) from "payroll automation" (not).
  3. Art. 6(3) exception check — if you land in an Annex III area, follow-up questions test whether the narrow-task exception applies.
  4. Transparency check (Art. 50) — systems that interact with people or generate content pick up transparency obligations regardless of risk level.

Evidence-based confidence

Each result carries a confidence rating derived from how strongly your answers match the rules — how specific your description was, and whether your sector cross-checks with the category. A low-confidence result is a prompt to refine your answers, not a verdict.

What you get

A risk level, the articles that drove it, the obligations that follow from it, and a written rationale you can keep as evidence that you performed the assessment — which itself is something regulators expect to see.

Classification is indicative tooling, not legal advice. For borderline systems, take the written rationale to legal counsel — it makes their review faster and cheaper.

Didn't find what you need?

Guardia AI provides compliance tooling, not legal advice. For official regulatory text, see EU Regulation 2024/1689.